VYPR
Unrated severityNVD Advisory· Published Sep 25, 2020· Updated Aug 4, 2024

CVE-2020-15521

CVE-2020-15521

Description

Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine Applications Manager before build 14730 is vulnerable to stored XSS via jsp/header.jsp.

Vulnerability

Zoho ManageEngine Applications Manager before version 14 build 14730 is vulnerable to stored cross-site scripting (XSS) in the jsp/header.jsp component. The application fails to sanitize user-supplied input before rendering it in the header, allowing an attacker to inject arbitrary HTML or JavaScript. This affects all versions prior to build 14730 [2].

Exploitation

An attacker must be authenticated to the Applications Manager console. The attacker can inject malicious script into a field that is later displayed in jsp/header.jsp. When other administrators view the affected page, the script executes in their browser session. No additional user interaction beyond viewing the page is required.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to theft of session cookies, manipulation of the application interface, or further actions such as creating new admin accounts or exfiltrating sensitive data.

Mitigation

The vulnerability is fixed in Zoho ManageEngine Applications Manager build 14730 (version 14) and later. Users should upgrade to this build or newer. No workarounds are documented in the available references [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.